¼ÓÄôóij×ÔÈ»Æø¹ÜµÀÔâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը

Ðû²¼Ê±¼ä 2023-04-28

1¡¢¼ÓÄôóij×ÔÈ»Æø¹ÜµÀÔâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը


¾ÝýÌå4ÔÂ26ÈÕ±¨µÀ  £¬¼ÓÄôóij×ÔÈ»Æø¹ÜÔâµ½¹¥»÷  £¬¿ÉÄÜ»áÒý·¢±¬Õ¨ ¡£Å¦Ô¼Ê±±¨³Æ  £¬Ð¹Â¶µÄÃÀ¹úÇ鱨ÎļþÕ¹ÏÖÁËÕâÒ»ÊÂÎñ ¡£ÆäÖÐÒ»·ÝÎļþ°üÀ¨ZaryaÓëFSBÔ±¹¤µÄ¶Ô»°  £¬ËûÃÇÔ¤¼ÆÀֳɵĹ¥»÷½«µ¼ÖÂÅ䯸վ±¬·¢±¬Õ¨  £¬²¢ÔÚ¼àÊÓ¼ÓÄôóÐÂÎű¨µÀ¿´ÊÇ·ñÓб¬Õ¨¼£Ïó ¡£¸ÃÎļþµÄÕæÊµÐÔÉÐδ»ñµÃ֤ʵ ¡£¼ÓÄôó×ÜÀíÈ·ÈÏÁËÕë¶Ô×ÔÈ»Æø¹ÜµÀµÄÍøÂç¹¥»÷  £¬µ«ËûÖ¸³ö¼ÓÄôóµÄÈκÎÄÜÔ´»ù´¡ÉèÊ©¶¼Ã»ÓÐÊܵ½ÏÖʵË𺦠¡£


https://securityaffairs.com/145307/cyber-warfare-2/canadian-gas-pipeline-disruptive-attack.html


2¡¢Alloy TaurusʹÓÃPingPullбäÌå¹¥»÷ÄϷǺÍÄá²´¶û


4ÔÂ26ÈÕ  £¬Unit 42³Æ×î½ü·¢Ã÷Alloy TaurusÍÅ»ïʹÓÃPingPullºóÃŵÄбäÌå¹¥»÷LinuxϵͳµÄ»î¶¯  £¬¸Ã»î¶¯Ö÷ÒªÕë¶ÔÄϷǺÍÄá²´¶û ¡£3ÔÂ7ÈÕ  £¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÉÏ´«µ½VirusTotalµÄPingPullµÄLinux±äÌå  £¬ËüµÄ¼ì²âÂʺÜÊǵÍ ¡£PingPullÖÐʹÓõÄÏÂÁî´¦Öóͷ£³ÌÐòÓëÔÚÁíÒ»¸ö¶ñÒâÈí¼þChina ChopperµÄÖз¢Ã÷µÄÏÂÁî´¦Öóͷ£³ÌÐòÏàËÆ ¡£±ðµÄ  £¬Unit 42»¹·¢Ã÷ÁËÒ»¸öеÄELFºóÃÅSword2033  £¬Á´½Óµ½ÏàͬµÄC2»ù´¡ÉèÊ©  £¬Ö§³ÖÉÏ´«¡¢Ð¹Â¶ÎļþºÍÖ´ÐÐÏÂÁîÈý¸ö»ù±¾¹¦Ð§ ¡£


https://unit42.paloaltonetworks.com/alloy-taurus/


3¡¢FIN7ÍÅ»ïʹÓÃ×î½üÐÞ¸´µÄVeeamÎó²î·Ö·¢ºóÃÅLizar


WithSecureÔÚ4ÔÂ26ÈÕÅû¶ÁËFIN7ÍÅ»ïÕë¶ÔVeeam±¸·Ý·þÎñÆ÷µÄ¹¥»÷»î¶¯ ¡£3ÔÂ28ÈÕ  £¬Ñо¿Ö°Ô±ÔÚÔËÐÐVeeam Backup & ReplicationÈí¼þµÄ·þÎñÆ÷Éϼì²âµ½³õʼ»î¶¯ ¡£ÓëVeeam BackupʵÀýÏà¹ØµÄSQL·þÎñÆ÷Àú³Ìsqlservr.exeÖ´ÐÐÁËÒ»¸öshellÏÂÁî  £¬¸ÃÏÂÁîÔÚÄÚ´æÖÐÏÂÔØ²¢Ö´ÐÐPowerShell¾ç±¾ ¡£ÕâЩPowerShell¾ç±¾µÄËùÓÐʵÀý¶¼ÊÇPowertrash dropper  £¬ËüÓÃÓÚ·Ö·¢ºóÃÅDiceloader£¨Ò²³ÆÎªLizar£© ¡£¸Ã»î¶¯µÄ³õʼ»á¼ûºÍÖ´ÐкܿÉÄÜÊÇͨ¹ý×î½üÐÞ¸´µÄVeeam Backup & ReplicationÎó²î£¨CVE-2023-27532£©ÊµÏÖµÄ ¡£


https://labs.withsecure.com/publications/fin7-target-veeam-servers


4¡¢ÎÚ¿ËÀ¼¾¯·½¾Ð²¶Ôø³öÊÛÁè¼Ý3ÒÚ¹«ÃñСÎÒ˽¼ÒÐÅÏ¢µÄÏÓÒÉÈË


ýÌå4ÔÂ26ÈÕ³Æ  £¬ÎÚ¿ËÀ¼ÍøÂ羯Ա¾Ð²¶ÁËÀ´×ÔNetishynµÄÒ»Ãû36ËêÄÐ×Ó  £¬×ïÃûÊdzöÊÛÁè¼Ý3ÒÚÎÚ¿ËÀ¼ºÍÅ·ÖÞ¸÷¹ú¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢ ¡£ÏÓÒÉÈËʹÓÃTelegramÏò¸ÐÐËȤµÄÂò¼ÒÍÆÏú±»µÁÊý¾Ý  £¬Æ¾Ö¤Êý¾ÝÁ¿¼°Æä¼ÛÖµ  £¬Òª¼ÛÔÚ500µ½2000ÃÀÔªÖ®¼ä ¡£Éæ¼°»¤ÕÕÊý¾Ý¡¢ÄÉ˰È˱àºÅ¡¢³öÉú֤ʵ¡¢¼ÝʻִÕÕºÍÒøÐÐÕË»§Êý¾ÝµÈÐÅÏ¢ ¡£¾ÝϤ  £¬Ö´·¨Ö°Ô±²éÊÕÁË36¸öÓ²ÅÌÇý¶¯Æ÷¡¢ÅÌËã»úºÍ·þÎñÆ÷×°±¸  £¬ÆäÖаüÀ¨¶à¸öÊý¾Ý¿â  £¬ÆäȪԴ½«Í¨ÊºóÐøÆÊÎöÈ·¶¨ ¡£


https://www.bleepingcomputer.com/news/security/ukrainian-arrested-for-selling-data-of-300m-people-to-russians/


5¡¢Linux°æ±¾µÄRTM LockerÕë¶ÔVMware ESXi·þÎñÆ÷


UptycsÔÚ4ÔÂ26ÈÕÐû²¼ÁËÒ»·Ý±¨¸æ  £¬ÆÊÎöÁËRTM LockerµÄÒ»¸öLinux±äÌå  £¬¸Ã±äÌå»ùÓÚÏÖÒÑÇýÖðµÄBabukÀÕË÷Èí¼þµÄÔ´´úÂë ¡£RTM LockerµÄLinux°æ±¾¼ÓÃܳÌÐòËÆºõÊÇרÃÅΪ¹¥»÷VMware ESXiϵͳ¿ª·¢µÄ  £¬ÓÉÓÚËü°üÀ¨ÁËÐí¶àÓÃÓÚ¹ÜÀíÐéÄâ»úµÄÏÂÁî ¡£ÓëBabukÒ»Ñù  £¬RTMʹÓÃËæ»úÊýÌìÉúºÍECDH¶ÔCurve25519¾ÙÐзǶԳƼÓÃÜ  £¬µ«ËüûÓÐʹÓÃSosemanuk  £¬¶øÊÇÒÀÀµChaCha20¾ÙÐжԳƼÓÃÜ ¡£Ñо¿Ö°Ô±³Æ  £¬ESXi°æ±¾µÄ±£´æ  £¬×ãÒÔ½«RTM Locker¹éÀàΪÕë¶ÔÆóÒµµÄÖØ´óÍþв ¡£


https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux


6¡¢LayerXÐû²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷Çå¾²µÄÊÓ²ìÆÊÎö±¨¸æ


¾Ý4ÔÂ26ÈÕ±¨µÀ  £¬LayerXÐû²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷Çå¾²µÄÊÓ²ìÆÊÎö±¨¸æ ¡£±¨¸æÖ¸³ö  £¬ÔÚÒÑÍù12¸öÔÂÖÐ  £¬87%µÄall-SaaSºÍ79%»ìÏýÇéÐÎÖеÄCISO¶¼ÂÄÀú¹ýÇå¾²ÊÂÎñ ¡£ÕÊ»§½ÓÊÜÊÇ×îÁîÈ˵£ÐĵÄÎÊÌâ  £¬48%µÄÈ˽«Æ¾Ö¤ÍøÂç´¹ÂÚÁÐΪΣº¦×î¸ßµÄä¯ÀÀÆ÷Íþв  £¬Æä´ÎÊǶñÒâä¯ÀÀÆ÷À©Õ¹(37%)¡¢¶ñÒâÈí¼þÏÂÔØ(9%)ºÍä¯ÀÀÆ÷Îó²î(6%) ¡£´ó´ó¶¼×éÖ¯½ÓÄÉÖÁÉÙÁ½ÖÖÇå¾²²½·¥À´µÖÓù´¹ÂÚ¹¥»÷  £¬79%ʹÓÃÍøÂçÇå¾²¹¤¾ß  £¬ÀýÈç·À»ðǽºÍSWG ¡£


https://go.layerxsecurity.com/2023-browser-security-survey